Course Description
This one-day instructor-led course covers theory and practice of High Availability in a complete Check Point Nokia IPSO security system. The course is designed to be hands-on, and students will implement in the course of their lab exercises a security system with minimal – known and quantified – single points of failure.
Who Should Take This Course?
Technical persons tasked with the design, installation, and operation of Nokia security solutions with high uptime targets or where systems cannot be easily taken down for scheduled maintenance and upgrade should attend this course. This would include operation of any system where pairing IPSO systems in a cluster or a resilient pair mitigates a single point of failure.
Course Fee:$995
Course Prerequisites
Persons attending this course must have attended NSA: Foundation or they should have passed NSA certification.
Course Objectives
After completion of this course, participants will be able to:
- Understand the theory of resilient design
- Understand the IPSO alternatives of clustering and VRRP (virtual router resilience)
- Understand how to combine these mechanisms with power provisions, appropriate switching technology and other related technologies to remove all single points of failure
- Install an end-to-end solution
Topics Covered
- Theory of resilient design
- VRRP – simplified, and traditional mode MC
- IPSO clustering
- Check Point clustering, cluster objects, synchronization, sync configuration, and tuning by protocol and by delayed sync
- Clustering integration with switches
- Dual power, dual hard drive mirroring
- Check Point multiple link/ISPs
- Static route priorities and failover
- Link aggregation
Course Outline
Introduction General HA Theory Hardware HA Theory Reducing Single Points of Failure Nokia HA Appliances Lab Design Initial Configuration Simplified and Full VRRP Integrating VRRP and Check Point VPN-1 NGX Nokia IP Clustering IP Clustering and VPN-1 Integration Link Aggregation ISP Link Redundancy Static Route Priority Failover
Note
NSA:HA does not cover the use of dynamic routing as a resilience mechanism. Dynamic routing and routing over Check Point VPN are covered in NSA:Connectivity which is a companion course ot NSA:HA, and is highly recommended if you need to understand all of your options in implementing a highly available system.